Privacy Policy

Effective Date: September 29, 2021
Last Updated:
September 7, 2026

This privacy policy sets out how we handle personal data. We care about how personal data are handled and we assure you that we observe all relevant legal requirements. We consider the protection of your privacy to be of paramount importance.

Scope of this Privacy Policy

This policy covers personal data handled by Flagright Data Technologies Inc. ("Flagright", "we") in connection with our website at https://flagright.com and our Platform, meaning the Flagright Console, our APIs, and related support.

Flagright handles personal data in two roles.

As controller, for data we decide the purposes for: website visitors, prospects, job applicants, employees and contractors, and the individual users our Clients provision to access the Platform. Sections 1 to 13 cover this.

As processor, for the data our Clients submit to the Platform about their own customers and transactions. The Client stays the controller under Art. 28 GDPR and we act only on their instructions, under our data processing agreement with them. This policy does not govern that processing. Section 14 explains how those requests are handled.

Throughout, Client means an organisation using the Platform, Platform User means an individual authorised to access the Console or APIs, and Client Data means data a Client submits about its own customers.

Contact information

General: hello[at]flagright.com

Data protection officer: gdpr[at]flagright.com

Where we operate

  • Legal entities and offices: 
    • Flagright Data Technologies Inc, USA
    • Flagright Ltd, UK
    • Flagright Pte. Ltd., Singapore
    • Flagright Private Limited, India
  • Platform hosting regions: Agreed with each Client

Your data may be accessed from or transferred to any of these places. For transfers outside the European Economic Area we rely on an adequacy decision, EU Standard Contractual Clauses, or another lawful mechanism. You can request a copy of the safeguards from gdpr[at]flagright.com.

What we collect

Website visitors and prospects. Contact and business details you submit. Online identifiers such as IP address, browser, operating system, referrer URL, and the time of the request. Social media and cookie identifiers.

Platform Users. Name, work email, job title, employer, role and permissions. Authentication data including credentials, MFA enrolment, and SSO identifiers. Access and audit logs recording login times, IP address, device, and actions taken in the Console. Support tickets and correspondence. Feature usage and error telemetry. Billing and contract contacts.

Client Data. Identity, contact, financial, transactional, and risk information about a Client's customers. We do not decide what a Client submits. See section 14.

We do not seek to collect special category data under Art. 9 GDPR about website visitors or Platform Users.

4. How we get it

Directly from you, when you fill in a form, contact us, raise a ticket, or use the Console.

Automatically, through server logs, cookies, pixels, and analytics instrumentation in our website and Console. Cookies are small text files stored on your device. Our cookie policy on Flagright’s website, www.flagright.com/cookie-policy lists each one and what it does.

From your organization, where a Client provisions your account or supplies contact details, and from its identity provider where SSO is used.

5. Why we collect it

  • To respond to inquiries and provide our services.
  • To run, secure, and support the Platform, including authentication and access control.
  • To detect and investigate abuse and security incidents.
  • To keep audit trails and meet our legal, regulatory, and contractual obligations.
  • To administer contracts and billing.
  • To improve and troubleshoot the Platform.
  • For marketing, website statistics, and our newsletter.

We collect only what the purpose requires. Optional fields are marked as optional. Platform accounts are provisioned with the minimum data needed to authenticate you and apply the permissions your organisation assigned. We do not use data for incompatible purposes without telling you and, where required, asking your consent.

6. Legal bases

  • Consent, Art. 6(1)(a), for marketing, non essential cookies, and data you volunteer.
  • Contract, Art. 6(1)(b), for providing the Platform and pre contractual steps.
  • Legal obligation, Art. 6(1)(c), where the law requires us to retain or disclose data.
  • Legitimate interests, Art. 6(1)(f), for security and abuse prevention, audit logging, statistics and performance experimentation, service improvement, and managing business relationships.

Where an employer provisioned your account, the contract runs between Flagright and the Client, and we rely on legitimate interests for your individual account data.

7. Your choices, and what happens if you decline

Consent is voluntary and you can withdraw it at any time. Withdrawal does not affect processing already carried out.

  • Marketing. Unsubscribe from any email or contact us. No other effect on your relationship with us.
  • Cookies. Accept or reject non essential cookies in our banner, or block them in your browser. Some functions of the website and Console may then not work fully.
  • Optional fields. You can leave them blank with no effect on your access.
  • Account data. Name, work email, and role are required to create and secure a Platform account. Without them we cannot authenticate you and access cannot be provided.
  • Audit and authentication logs. Generated as a necessary part of a secured service. These cannot be turned off while an account is active, because our Clients and their supervisors rely on them.
  • Form contact details. Needed to reply to you. Without them we cannot respond.

We tell you at the point of collection where information is required.

8. How long we keep it

  • Consent based data: until you withdraw consent.
  • Contract data: until the relationship ends or legal retention periods expire.
  • Legitimate interest data: until your overriding interest requires deletion or anonymisation.
  • Platform account data: deleted or anonymised within 90 days of account deactivation, unless a longer retention period is required by applicable law.
  • Access and audit logs: Set by the Client in its agreement with Flagright.
  • Support records: Set by the Client in its agreement with Flagright.
  • Client Data: Set by the Client in its agreement with Flagright.
  • Privacy request records: minimum three years from closure, for audit.

9. Who we share it with, and why

  • Cloud hosting and infrastructure providers, to run the website and Platform.
  • Analytics providers, to measure and improve usage.
  • Regulators, law enforcement, and courts, where required by law or lawful order.

Data is being transferred to third countries outside the European Union. This takes place on the basis of contractual regulations provided by law, which are intended to ensure adequate protection of your data and which you can view on request. We do not sell personal data and do not share it for anyone else's marketing.

10. Security

We have taken extensive technical and organisational measures to secure your data against potential risks, such as unauthorised login or access, unauthorised perusal, amendment or distribution, as well as against loss, deletion or misuse.

In order to protect your personal data against unauthorised access by third parties when being transmitted, we secure data transmissions, if necessary, using SSL encryption. This is a standard encryption procedure for online services, particularly for the Internet.

11. Cookies and analytics

Like almost all website operators, we use analytical tools in the form of tracking software to ascertain the number of users using our website and how frequently they visit. To enable us to optimize our website and our service, we use Google Analytics and PostHog (for Console only).

Google Analytics is a web analysis service provided by Google Ireland Limited ("Google"), a company incorporated and regulated under Irish law. Google Analytics uses "cookies"—text files stored on your computer and used to analyze your website usage. The information generated by the cookie about your use of this website (including your IP address) will be sent to a Google server in the USA and stored there. However, if IP anonymization is enabled, Google will first abbreviate your IP address within the European Union or the European Economic Area. Google will use this information to analyze your use of the website, compile reports about website activities, and perform other services connected with the use of the website and the Internet. The IP address transmitted by your browser as part of Google Analytics will not be merged or combined with other data by Google.

PostHog is used solely for Console to understand user interactions and improve the user experience. PostHog collects and processes user interaction data in a privacy-conscious manner. PostHog may use cookies to help analyze and monitor activity specifically within the Console. Any data collected by PostHog is stored within the EU and processed in accordance with applicable privacy laws.

You can prevent cookies from being stored by applying the appropriate settings in your browser software; however, please note that in this case, you may not be able to use all of the functions of this website to their full extent.

Your cookie choices are in section 7.

12. Automated processing

The Platform applies rules, risk scoring, and machine learning to transactions and customer records on our Clients' behalf. Flagright does not decide the outcomes. The Client configures the logic, decides how outputs are used, and is responsible for any decision with legal or similarly significant effects under Art. 22 GDPR.

We do not carry out automated decision making with legal or similarly significant effects on website visitors or Platform Users.

13. Your rights and how to use them

Where Flagright is the controller, you can ask us to give you access to your data, correct it, delete or block it, restrict how we process it, or send it to another provider. You can object to processing based on legitimate interests, and withdraw consent at any time. You also have the right to lodge a complaint with the competent data protection supervisory authority.

To make a request, email gdpr[at]flagright.com with the subject "Data Subject Request". Platform Users can also raise one through their organization's usual support channel.

What we do. We log the request, acknowledge it, verify your identity, decide whether we are controller or processor, assess the request, action it, and confirm what we did. We respond within the time the law allows. There is no charge.

Verifying you. Checks are proportionate to how sensitive the data is. We may confirm the request came from the registered email, match details against our records, or ask for a government issued ID where the data is sensitive or we cannot verify you otherwise. Authorised agents must evidence their authority. If we cannot verify you, we refuse the request and record why.

When we cannot comply. We may not be able to action a request in full where the law requires us to keep the data, it is needed to establish, exercise, or defend legal claims, it is needed to perform a contract you are party to, the request conflicts with freedom of expression and information, or the request is manifestly unfounded or excessive. Platform account and audit data generally cannot be deleted while the Client relationship is active. We always tell you why.

14. Requests about Client Data

Our Clients are the controllers of the data they submit to the Platform. We do not maintain profiles of their customers and we do not answer these requests ourselves.

If you are a customer of one of our Clients, contact that institution directly. If you contact us, we refer the request to the controller without undue delay and assist them as our data processing agreement requires. Your rights are exercised against the controller, who will verify your identity before acting, which may require a government issued ID.

15. Changes

We may amend this policy at any time with future effect. Material changes are communicated to Clients through the channels in their agreement, notified to Platform Users, and recorded in the revision history above.

Date of issue: 7 September 2026